mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-30 20:00:10 +00:00
Merge release-23.11 into staging-next-23.11
This commit is contained in:
@@ -20,7 +20,7 @@
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "palemoon-bin";
|
||||
version = "33.0.2";
|
||||
version = "33.1.0";
|
||||
|
||||
src = finalAttrs.passthru.sources."gtk${if withGTK3 then "3" else "2"}";
|
||||
|
||||
@@ -158,11 +158,11 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
in {
|
||||
gtk3 = fetchzip {
|
||||
urls = urlRegionVariants "gtk3";
|
||||
hash = "sha256-Kahnwlj9PIWB24lvH6h9cZK459NW2Vo2g6ckuv0Ax48=";
|
||||
hash = "sha256-qjztSvNL7KNFG3sszgk5qH77do0HFQ8YTrgjFi2ZM00=";
|
||||
};
|
||||
gtk2 = fetchzip {
|
||||
urls = urlRegionVariants "gtk2";
|
||||
hash = "sha256-XOiLGmU8O96clUpnp/OkzXmWR1PJ2AdzbVFj6adbcvY=";
|
||||
hash = "sha256-q4zAmnCN9SHGb8PthjAx7d5FKq/oAQ8c0R+U1SWqjAA=";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -2,14 +2,14 @@
|
||||
let
|
||||
versions =
|
||||
if stdenv.isLinux then {
|
||||
stable = "0.0.50";
|
||||
ptb = "0.0.80";
|
||||
canary = "0.0.357";
|
||||
stable = "0.0.51";
|
||||
ptb = "0.0.81";
|
||||
canary = "0.0.369";
|
||||
development = "0.0.17";
|
||||
} else {
|
||||
stable = "0.0.301";
|
||||
ptb = "0.0.109";
|
||||
canary = "0.0.477";
|
||||
stable = "0.0.302";
|
||||
ptb = "0.0.110";
|
||||
canary = "0.0.486";
|
||||
development = "0.0.39";
|
||||
};
|
||||
version = versions.${branch};
|
||||
@@ -17,15 +17,15 @@ let
|
||||
x86_64-linux = {
|
||||
stable = fetchurl {
|
||||
url = "https://dl.discordapp.net/apps/linux/${version}/discord-${version}.tar.gz";
|
||||
hash = "sha256-6VXdVLk7Z8NGQMiSdgBRd8NIueUktkId6BXYKNABb+4=";
|
||||
hash = "sha256-w8zLeaqJXdbI67X/UDxSLQxZei5eraa/BkMZa+GDpYk=";
|
||||
};
|
||||
ptb = fetchurl {
|
||||
url = "https://dl-ptb.discordapp.net/apps/linux/${version}/discord-ptb-${version}.tar.gz";
|
||||
hash = "sha256-y/ntnHIYcY35Jszh0PrFy395eJ5dBWwLNpzHMoSZuNA=";
|
||||
hash = "sha256-/kM23y4Hx/0HwIOQvd+4Y429s/6Q+coa27hgI2U3EcU=";
|
||||
};
|
||||
canary = fetchurl {
|
||||
url = "https://dl-canary.discordapp.net/apps/linux/${version}/discord-canary-${version}.tar.gz";
|
||||
hash = "sha256-sDwC5kPzAfvQmsrq6M/GPFtUaT9pNAEB4uGI5Mn3oXs=";
|
||||
hash = "sha256-Ohfp5ypvdmjr5rYR1usdVoEuVwOALRozysIjT/v75Qs=";
|
||||
};
|
||||
development = fetchurl {
|
||||
url = "https://dl-development.discordapp.net/apps/linux/${version}/discord-development-${version}.tar.gz";
|
||||
@@ -35,15 +35,15 @@ let
|
||||
x86_64-darwin = {
|
||||
stable = fetchurl {
|
||||
url = "https://dl.discordapp.net/apps/osx/${version}/Discord.dmg";
|
||||
hash = "sha256-h7C1wCKtUGcMFUhoKVdD7Vq9TGUaXfmjlVhwmRdhqYw=";
|
||||
hash = "sha256-Xt0ef+ogGlPA4ebxuAsGQKeMVDoTB58jCRcyM1fHjYE=";
|
||||
};
|
||||
ptb = fetchurl {
|
||||
url = "https://dl-ptb.discordapp.net/apps/osx/${version}/DiscordPTB.dmg";
|
||||
hash = "sha256-xxLnzELuI0X2r/weP1K2Bb51uRh1JjR72p7cXzy12Kc=";
|
||||
hash = "sha256-hkRO/4YD1j4gsp+r3+md3ND/xtNmdutJiXlY3UIecIY=";
|
||||
};
|
||||
canary = fetchurl {
|
||||
url = "https://dl-canary.discordapp.net/apps/osx/${version}/DiscordCanary.dmg";
|
||||
hash = "sha256-xEDtEtZNhOTtz+zRLLQBSeLbntlVAVQsocAGyAaVePM=";
|
||||
hash = "sha256-c7KNWsV+pultD+HqRNonSOW9PCGx1AajCfnc94Dokwc=";
|
||||
};
|
||||
development = fetchurl {
|
||||
url = "https://dl-development.discordapp.net/apps/osx/${version}/DiscordDevelopment.dmg";
|
||||
|
||||
@@ -0,0 +1,74 @@
|
||||
Based on upstream dd5fec92730562af6f96891291cd4e102b80bfcc, adjusted to
|
||||
apply cleanly to 1.7.0
|
||||
|
||||
diff --git a/src/sip.c b/src/sip.c
|
||||
index 20a2d81..f2dde5c 100644
|
||||
--- a/src/sip.c
|
||||
+++ b/src/sip.c
|
||||
@@ -264,7 +264,7 @@ sip_validate_packet(packet_t *packet)
|
||||
uint32_t plen = packet_payloadlen(packet);
|
||||
u_char payload[MAX_SIP_PAYLOAD];
|
||||
regmatch_t pmatch[4];
|
||||
- char cl_header[10];
|
||||
+ char cl_header[MAX_CONTENT_LENGTH_SIZE];
|
||||
int content_len;
|
||||
int bodylen;
|
||||
|
||||
@@ -291,7 +291,15 @@ sip_validate_packet(packet_t *packet)
|
||||
return VALIDATE_PARTIAL_SIP;
|
||||
}
|
||||
|
||||
- strncpy(cl_header, (const char *)payload + pmatch[2].rm_so, (int)pmatch[2].rm_eo - pmatch[2].rm_so);
|
||||
+ // Ensure the copy length does not exceed MAX_CONTENT_LENGTH_SIZE - 1
|
||||
+ int cl_match_len = pmatch[2].rm_eo - pmatch[2].rm_so;
|
||||
+ if (cl_match_len > MAX_CONTENT_LENGTH_SIZE - 1) {
|
||||
+ cl_match_len = MAX_CONTENT_LENGTH_SIZE - 1;
|
||||
+ }
|
||||
+
|
||||
+ strncpy(cl_header, (const char *)payload + pmatch[2].rm_so, cl_match_len);
|
||||
+ cl_header[cl_match_len] = '\0'; // Ensuring null termination
|
||||
+
|
||||
content_len = atoi(cl_header);
|
||||
|
||||
// Check if we have Body separator field
|
||||
@@ -756,7 +764,7 @@ void
|
||||
sip_parse_extra_headers(sip_msg_t *msg, const u_char *payload)
|
||||
{
|
||||
regmatch_t pmatch[4];
|
||||
- char warning[10];
|
||||
+ char warning[MAX_WARNING_SIZE];
|
||||
|
||||
// Reason text
|
||||
if (regexec(&calls.reg_reason, (const char *)payload, 2, pmatch, 0) == 0) {
|
||||
@@ -766,8 +774,16 @@ sip_parse_extra_headers(sip_msg_t *msg, const u_char *payload)
|
||||
|
||||
// Warning code
|
||||
if (regexec(&calls.reg_warning, (const char *)payload, 2, pmatch, 0) == 0) {
|
||||
- strncpy(warning, (const char *)payload + pmatch[1].rm_so, (int)pmatch[1].rm_eo - pmatch[1].rm_so);
|
||||
- msg->call->warning = atoi(warning);
|
||||
+
|
||||
+ // Ensure the copy length does not exceed MAX_WARNING_SIZE - 1
|
||||
+ int warning_match_len = pmatch[1].rm_eo - pmatch[1].rm_so;
|
||||
+ if (warning_match_len > MAX_WARNING_SIZE - 1) {
|
||||
+ warning_match_len = MAX_WARNING_SIZE - 1;
|
||||
+ }
|
||||
+ strncpy(warning, (const char *)payload + pmatch[1].rm_so, warning_match_len);
|
||||
+ warning[warning_match_len] = '\0'; // Ensuring null termination
|
||||
+
|
||||
+ msg->call->warning = atoi(warning);
|
||||
}
|
||||
}
|
||||
|
||||
diff --git a/src/sip.h b/src/sip.h
|
||||
index 78afdc2..a9fd06e 100644
|
||||
--- a/src/sip.h
|
||||
+++ b/src/sip.h
|
||||
@@ -45,6 +45,8 @@
|
||||
#include "hash.h"
|
||||
|
||||
#define MAX_SIP_PAYLOAD 10240
|
||||
+#define MAX_CONTENT_LENGTH_SIZE 10
|
||||
+#define MAX_WARNING_SIZE 10
|
||||
|
||||
//! Shorter declaration of sip_call_list structure
|
||||
typedef struct sip_call_list sip_call_list_t;
|
||||
@@ -27,6 +27,7 @@ stdenv.mkDerivation rec {
|
||||
url = "https://github.com/irontec/sngrep/commit/ad1daf15c8387bfbb48097c25197bf330d2d98fc.patch";
|
||||
hash = "sha256-g8fxvxi3d7jmZEKTbxqw29hJbm/ShsKKxstsOUGxTug=";
|
||||
})
|
||||
./1.7.0-CVE-2024-3119-CVE-2024-3120.patch
|
||||
];
|
||||
|
||||
nativeBuildInputs = [
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{ callPackage, fetchurl, lib, stdenv
|
||||
, ocamlPackages, coqPackages, rubber, hevea, emacs
|
||||
, version ? "1.7.1"
|
||||
, version ? "1.7.2"
|
||||
, ideSupport ? true
|
||||
, wrapGAppsHook
|
||||
}:
|
||||
@@ -12,7 +12,7 @@ stdenv.mkDerivation rec {
|
||||
src = fetchurl {
|
||||
url = "https://why3.gitlabpages.inria.fr/releases/${pname}-${version}.tar.gz";
|
||||
hash = {
|
||||
"1.7.1" = "sha256-rG1hcxFhQ2PlE9RTz9ELliDjCuSzLnJ1togRY637cU4=";
|
||||
"1.7.2" = "sha256-VaSG/FiO2MDdSSFXGJJrIylQx0LPwtT8AF7TpPVZhCQ=";
|
||||
"1.6.0" = "sha256-hFvM6kHScaCtcHCc6Vezl9CR7BFbiKPoTEh7kj0ZJxw=";
|
||||
}."${version}";
|
||||
};
|
||||
|
||||
@@ -2,16 +2,16 @@
|
||||
|
||||
rustPlatform.buildRustPackage rec {
|
||||
pname = "cargo-bloat";
|
||||
version = "0.11.1";
|
||||
version = "0.12.0";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "RazrFalcon";
|
||||
repo = pname;
|
||||
rev = "v${version}";
|
||||
sha256 = "sha256-lCA7C1G2xu65jn3/wzj6prWSrjQz3EqqJyMlPR/HRFs=";
|
||||
hash = "sha256-vPk6ERl0VM1TjK/JRMcXqCvKqSTuw78MsmQ0xImQyd4=";
|
||||
};
|
||||
|
||||
cargoSha256 = "sha256-fOenXn5gagFss9DRDXXsGxQlDqVXZ5LZcdM4WsXAyUU=";
|
||||
cargoHash = "sha256-6fMFGLH16Z1O+ETlr0685TXHup1vJetfzPdNC2Lw9uM=";
|
||||
|
||||
meta = with lib; {
|
||||
description = "A tool and Cargo subcommand that helps you find out what takes most of the space in your executable";
|
||||
@@ -19,6 +19,6 @@ rustPlatform.buildRustPackage rec {
|
||||
license = licenses.mit;
|
||||
platforms = platforms.unix;
|
||||
maintainers = with maintainers; [ xrelkd matthiasbeyer ];
|
||||
mainProgram = "cargo-bloat";
|
||||
};
|
||||
}
|
||||
|
||||
@@ -9,16 +9,16 @@
|
||||
|
||||
rustPlatform.buildRustPackage rec {
|
||||
pname = "cargo-deny";
|
||||
version = "0.14.21";
|
||||
version = "0.14.22";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "EmbarkStudios";
|
||||
repo = "cargo-deny";
|
||||
rev = version;
|
||||
hash = "sha256-d5qgljNuEfh9kYQU+jP4tgyly6i7hETFC5tEY67Yq8g=";
|
||||
hash = "sha256-04CRMlH31MzYpE2pRUrbAvSojbxan4ktqX9J/zjeTkk=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-u1cayvVatGg03Q3xShC/0ymE8EGHyYFrZD3Q8UD8Mm8=";
|
||||
cargoHash = "sha256-Nutx3Dvvh7qvgAtengWw0kJve4Ent9y7OXgovUZWTLE=";
|
||||
|
||||
nativeBuildInputs = [
|
||||
pkg-config
|
||||
|
||||
@@ -64,11 +64,11 @@ let
|
||||
in
|
||||
stdenv.mkDerivation rec {
|
||||
pname = "freeipa";
|
||||
version = "4.11.0";
|
||||
version = "4.11.1";
|
||||
|
||||
src = fetchurl {
|
||||
url = "https://releases.pagure.org/freeipa/freeipa-${version}.tar.gz";
|
||||
sha256 = "sha256-l/e2Dq/ako41QWEZyJCD+PA44PzTnzC8B7jYAm/Tt6Q=";
|
||||
sha256 = "sha256-Ubq2xAqBvjUwrzD2R6tB0i1WsdA0Y0jnJLgi4p4r8D4=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [
|
||||
|
||||
23
pkgs/servers/search/qdrant/1.6.1-CVE-2024-2221.patch
Normal file
23
pkgs/servers/search/qdrant/1.6.1-CVE-2024-2221.patch
Normal file
@@ -0,0 +1,23 @@
|
||||
Based on upstream 3ab8ec7d14178bb2ac39a4bcc972f2258254196e with unnecessary
|
||||
conflicting hunk dropped
|
||||
|
||||
diff --git a/src/actix/api/snapshot_api.rs b/src/actix/api/snapshot_api.rs
|
||||
index b8b40c6b..0fbed314 100644
|
||||
--- a/src/actix/api/snapshot_api.rs
|
||||
+++ b/src/actix/api/snapshot_api.rs
|
||||
@@ -75,6 +75,15 @@ pub async fn do_save_uploaded_snapshot(
|
||||
) -> std::result::Result<Url, StorageError> {
|
||||
let filename = snapshot
|
||||
.file_name
|
||||
+ // Sanitize the file name:
|
||||
+ // - only take the top level path (no directories such as ../)
|
||||
+ // - require the file name to be valid UTF-8
|
||||
+ .and_then(|x| {
|
||||
+ Path::new(&x)
|
||||
+ .file_name()
|
||||
+ .map(|filename| filename.to_owned())
|
||||
+ })
|
||||
+ .and_then(|x| x.to_str().map(|x| x.to_owned()))
|
||||
.unwrap_or_else(|| Uuid::new_v4().to_string());
|
||||
let collection_snapshot_path = toc.snapshots_path_for_collection(collection_name);
|
||||
if !collection_snapshot_path.exists() {
|
||||
@@ -23,6 +23,7 @@ rustPlatform.buildRustPackage rec {
|
||||
|
||||
patches = [
|
||||
./1.6.1-CVE-2024-3078.patch
|
||||
./1.6.1-CVE-2024-2221.patch
|
||||
];
|
||||
|
||||
cargoLock = {
|
||||
|
||||
@@ -27,6 +27,11 @@ buildGoModule rec {
|
||||
url = "https://github.com/authzed/spicedb/commit/ef443c442b96909694390324a99849b0407007fe.patch";
|
||||
hash = "sha256-8xXM0EBxJ0hI7RtURFxmRpYqGdSGZ/jZVP4KAuh2E/U=";
|
||||
})
|
||||
(fetchpatch {
|
||||
name = "CVE-2024-32001.patch";
|
||||
url = "https://github.com/authzed/spicedb/commit/a244ed1edfaf2382711dccdb699971ec97190c7b.patch";
|
||||
hash = "sha256-tdSqo7tFXs/ea5dIKV9Aikva9Za0Hj1Ng4LeCAQX9DA=";
|
||||
})
|
||||
];
|
||||
|
||||
vendorHash = "sha256-r0crxfE3XtsT4+5lWNY6R/bcuxq2WeongK9l7ABXQo8=";
|
||||
|
||||
@@ -17087,7 +17087,6 @@ with pkgs;
|
||||
inherit (darwin.apple_sdk.frameworks) Security;
|
||||
};
|
||||
cargo-binutils = callPackage ../development/tools/rust/cargo-binutils { };
|
||||
cargo-bloat = callPackage ../development/tools/rust/cargo-bloat { };
|
||||
cargo-bolero = callPackage ../development/tools/rust/cargo-bolero { };
|
||||
cargo-bundle = callPackage ../development/tools/rust/cargo-bundle { };
|
||||
cargo-bundle-licenses = callPackage ../development/tools/rust/cargo-bundle-licenses { };
|
||||
|
||||
Reference in New Issue
Block a user